When a CDN cache miss happens, the request hits your origin server. Origin protection (locking down direct access) prevents attackers from bypassing the CDN. For law firm sites behind Cloudflare, always configure origin firewall rules to only accept Cloudflare IPs.